Privacy Policy
Effective date: August 5, 2026
Akacia is a client-reporting and account-management portal operated by Turn Up Technologies ("we", "us", "our"). This policy explains what data the Akacia platform collects, why we collect it, how it is stored and protected, and the choices you have. It applies to the Akacia website and portal (the "Service").
1. What data we collect, and why
We collect and process the following categories of data:
- Google Ads account data. Campaign, ad group, keyword, ad, search term, conversion, budget and performance data (impressions, clicks, cost, conversions and related metrics) from the Google Ads accounts our agency clients have authorized us to manage. We use this data to monitor account health, generate findings and recommendations, display live dashboards and reports, and carry out the campaign changes our clients have engaged us to make.
- Account and profile information. The name, email address, role and sign-in credentials (stored only as salted cryptographic hashes — we never store plain-text passwords) of the people our clients ask us to give portal access to. We use this to authenticate users and control who can see which account.
- Usage and audit records. Records of significant actions taken in the portal (for example a campaign change or a user being added), kept so that account activity is accountable and traceable.
- Assistant conversations. Messages exchanged with the in-portal AI assistant, retained so a user's conversation is available to them across sessions. Conversations are scoped to the user and client account they belong to.
We do not collect data for advertising to you, we do not build profiles for any purpose other than operating the Service, and we collect no more data than the Service needs.
2. How we access Google data
Akacia accesses Google Ads data through the official Google Ads API, using OAuth authorization granted by our agency clients (or by us on their behalf, under a manager account they have linked). In plain terms:
- Access exists only because the account owner authorized it. Authorization is scoped to Google Ads and does not extend to other Google services or personal data.
- We act on behalf of our agency clients, under the management engagement they have with us, to monitor and manage their advertising accounts.
- Authorization can be revoked at any time from the Google account's security settings (myaccount.google.com → Security → Third-party access) or by unlinking the account, after which the Service can no longer read the account.
3. Google API Services User Data Policy
Akacia's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In accordance with those Limited Use requirements:
- Data obtained through Google APIs is used only to provide and improve the user-facing features of the Service — dashboards, findings, reports and the account assistant.
- We do not transfer this data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice.
- We do not use this data for serving advertisements.
- We do not allow humans to read this data except with the account owner's permission, where necessary for security or compliance, or to operate and troubleshoot the Service.
4. How data is stored and protected
- Data is stored in access-controlled cloud infrastructure: a managed MongoDB database for portal data (users, settings, conversations, audit records and cached account snapshots) and encrypted environment configuration for API credentials. All data is encrypted in transit (TLS) and at rest by our hosting providers.
- OAuth tokens and API credentials are stored as server-side secrets, are never exposed to browsers, and are never written to client-side code.
- Passwords are stored only as salted scrypt hashes and cannot be recovered in plain text.
- Each client account's data is logically isolated. A signed session determines which account a user can see, and server-side checks enforce it on every request.
5. Who can access it
Internal staff only. Access to account data is limited to authorized Turn Up Technologies personnel who need it to operate the Service and manage the client's advertising — and to the users each client has asked us to provision, who can see only their own account. Administrative areas of the portal are restricted by role and enforced before a page renders.
6. How long we keep it
- Google Ads data is read live from the Google Ads API. Cached snapshots and mirrors kept for performance and reliability are short-lived and continuously replaced.
- Portal data (users, settings, conversations, audit records) is retained for as long as the client engagement is active.
- When an engagement ends, or on a verified request from the account owner, we delete the associated account data within 30 days, except where a record must be retained to comply with a legal obligation.
7. What we never do
- We do not sell your data. Ever.
- We do not share advertising data with third parties, other than the infrastructure providers that host the Service (cloud hosting, managed database, email delivery and the AI provider that powers the assistant), each acting under contract as a processor for us and only to run the Service.
- We do not use client data to train models or for any purpose beyond operating the Service.
- We do not show ads in the Service, and we do not use your data to target ads anywhere.
8. Your choices and rights
- You can revoke Google authorization at any time, as described in section 2.
- You can ask us to correct, export or delete data we hold about you or your account by emailing us at the address below. We respond to verified requests within 30 days.
- Depending on where you live, you may have additional statutory rights (such as under GDPR or CCPA); we honour those rights for all users regardless of location.
9. Changes to this policy
If we make material changes to this policy, we will update the effective date above and notify active clients by email or through the portal before the changes take effect.
10. Contact
For privacy questions, data requests or anything in this policy, contact Turn Up Technologies at akacia@turnuptechnologies.co.